❌

Normal view

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

19 August 2026 at 11:34
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

19 August 2026 at 06:01
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

18 August 2026 at 17:47
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

18 August 2026 at 12:38
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

18 August 2026 at 09:10
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line "[Important] Your SafePal Order

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

17 August 2026 at 21:03
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

17 August 2026 at 18:44
Cybersecurity researchers at WizΒ have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's publicΒ snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present inΒ .github/workflows/jira_issue.yml, which ran when a

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

17 August 2026 at 10:52
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. TheΒ advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosedΒ remote code executionΒ in the

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

14 August 2026 at 13:08
The threat actor known as HoneyMyte (akaΒ Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan,

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

14 August 2026 at 11:07
Cybersecurity researchers have detailed a post-exploitation technique that enables theΒ Chrome DevTools Protocol (CDP)Β inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes that an operator already has code execution on the Windows host and does not involve

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

12 August 2026 at 11:47
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing,

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

12 August 2026 at 08:04
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

11 August 2026 at 20:10
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

11 August 2026 at 19:08
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

11 August 2026 at 16:47
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked asΒ CVE-2026-55040Β (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

11 August 2026 at 12:05
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

11 August 2026 at 12:04
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with. That decision carries a cost for

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

11 August 2026 at 11:35
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

11 August 2026 at 10:48
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

11 August 2026 at 10:24
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

❌